Trivy, Not LiteLLM Behind the 2,500 Org Compromise

A massive supply chain attack has left thousands of organizations vulnerable to cyber threats, with a surprising twist: most of the compromised systems were actually infected by a previous vulnerability in a popular security scanner, rather than the original malware. According to SOCRadar’s analysis, more than 2,500 organizations were likely affected by the LiteLLM attack, … Read more

Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor’s Office

A potentially far-reaching data breach has struck the Scottish government, with thousands of employees’ personal information potentially compromised due to a third-party supplier’s security lapse. The breach is linked to an external contractor that was involved in an online data maturity assessment organized by the national government. The assessment, which aimed to gauge various agencies’ … Read more

Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI

A Perfect Storm of Vulnerabilities: Can AI-Driven Solutions Rescue the National Vulnerability Database? The cybersecurity landscape has never been more challenging. A tidal wave of software vulnerabilities, fueled in part by artificial intelligence-augmented research and scanning, has left many organizations struggling to keep up. In an effort to stay ahead of this trend, the National … Read more

Mission-Driven Security: Inside a Global Bank’s Defense

Cybersecurity’s New Frontier: How a Global Bank’s CISO is Redefining Security Leadership In an era where cyber threats evolve at breakneck speed and financial institutions remain prime targets for sophisticated adversaries, the role of the chief information security officer (CISO) has never been more critical. Cezary Piekarski, group CISO at global bank Standard Chartered, is … Read more

What Boards Need to Know About Tech Risk

Boards Underestimate Technology Risks Until It’s Too Late Technology has become an integral part of modern business operations, and its risks are often hidden in plain sight. Despite this, many boardrooms underestimate technology risk until it becomes a full-blown crisis. This is largely due to the way technology investments are perceived: as opportunities for growth … Read more

Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor’s Office

Scottish Government’s Data Maturity Programme Exposed: Thousands of Employees’ Personal Info at Risk A potentially far-reaching data breach has struck Scotland’s government, leaving thousands of employees vulnerable to targeted attacks. The breach occurred when a third-party supplier, which had been contracted by multiple Scottish government agencies, experienced a security incident during an online data maturity … Read more

Max severity SAP Commerce Cloud flaw now targeted in attacks

A Critical SAP Commerce Cloud Flaw is Being Exploited in Real-World Attacks, Just Days After Patch Release A maximum-severity vulnerability in SAP’s Commerce Cloud platform has been targeted by attackers just three days after the company released a patch to fix it. The flaw, tracked as CVE-2026-58231, allows an unauthenticated attacker to execute arbitrary code … Read more

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

Cybersecurity experts have been sounding the alarm about the growing threat of account takeover (ATO) attacks on Google Workspace platforms. However, a recent wave of breaches at Vercel and Composio suggests that these incidents are not isolated events, but rather the same attack pattern being executed against different targets. This revelation has significant implications for … Read more